Do you need a new router to get WPA3?
"Upgrade to WPA3" is easy advice to give and annoying advice to act on, because it is unclear whether it means changing a setting or buying hardware. The answer is knowable in about five minutes, and for a lot of households it turns out to be a setting. This walks through finding out, and what each possible answer means — including the one where your internet provider should be handing you a replacement rather than you buying one.
The three outcomes
- WPA3 is offered: select it. FTC — WPA3 is "the newer — and best — encryption available."
- Only WPA2 AES/PSK is offered: that is acceptable. CISA’s list is "WPA3 Personal or WPA2 AES (also referred to as WPA2 Pre-Shared Key [PSK])".
- Only WEP, WPA, or WPA2 TKIP: CISA says the router must be replaced or upgraded by the ISP; FTC calls such routers "outdated and not secure".
- If the router came from your internet provider, the replacement is theirs to supply — ask before buying.
- NIST IR 8425A (September 2024) sets what a consumer router should be capable of, which is a better shopping guide than a generation number.
Probably not, and here is how to be sure
Probably not, if the router is recent. Possibly yes, if it came with a broadband contract several years ago and has not been touched since.
Either way the question is settled by looking, not by guessing from the age of the box. Routers that support WPA3 sometimes ship with it switched off, and routers that do not support it sometimes gain it through a firmware update.
Finding out what yours supports
- Find the router’s admin address. It is usually printed on a label on the device, alongside the default login. If not, it is in the manufacturer’s documentation.
- Log in. If you have never changed the administrator password, this is also the moment to fix that — CISA wants it long, random and unique, because default credentials may be publicly available.
- Open the wireless settings and find the security or encryption dropdown.
- Read every option in that list, not just the one currently selected. That list is your answer.
- Before concluding, check for a firmware update and apply it, then look at the list again. WPA3 support has been added to some models this way.
What each finding means
- WPA3 Personal or WPA3-SAE is present. No purchase needed. Select it, reconnect your devices, and deal with anything that objects by moving it to the guest network.
- The best option is WPA2 with AES, or WPA2-PSK. You are inside CISA’s acceptable set and inside the FTC’s. There is no urgency here. Replace the router when you were going to anyway.
- The best option is WPA2 with TKIP, WPA, or WEP. This is the replacement case. CISA puts all three in the same category, and the FTC describes routers offering only WPA or WEP as outdated and not secure.
- The router is your provider’s. Before spending anything, ask them. CISA’s wording includes the router being "upgraded by the ISP", and provider-supplied hardware is usually replaced free when it is out of date.
What a replacement should be able to do
If you are buying, the useful specification is not a generation number. NIST IR 8425A, published September 2024, sets out recommended cybersecurity requirements for consumer-grade router products, and its list makes a good set of questions to ask.
It specifies that routers should ship with unique initial passwords that are required to be changed to a strong password or passphrase on installation — meaning a model still using one shared default password across every unit is behind the standard. It requires the ability to keep software and firmware up to date, with protection against firmware rollback attacks. It asks for secure-by-design principles that minimise the number of interfaces, both logical and physical. And it requires the router to be restorable to a secure default, uninitialised configuration.
In shopping terms: does it get security updates, for how long, and can it install them itself? Those questions do more for you than the marketing on the front of the box.
What a new router will not fix
Buying hardware does not configure it. A new router with the default administrator password, WPS enabled and remote management on is not better off than an old one, and the FTC’s list applies just the same: unique administrative username, password and network name; firmware updates; remote management off; WPS and UPnP off; firewall on; log out of the admin account when done; and a guest network.
It also does nothing about the devices attached to it. CISA’s instruction to connect smart home and IoT devices to guest Wi-Fi, where internet access is all they require, is independent of which router you own and does more for most households than the encryption upgrade that prompted the purchase.
Sources: CISA Project Upskill, Module 5 · FTC — How to secure your home Wi-Fi network · NIST IR 8425A — Requirements for consumer-grade router products
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from CISA, the FTC and NIST. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.